Enhancing Application Security with Runtime Monitoring with Jeff Williams | RSAC Conference 2025
Jeff Williams from Contrast Security discusses the critical role of application security. He highlights the necessity of runtime security to detect vulnerabilities during code execution. The concept of the deployment event horizon is introduced, revealing gaps in traditional security. Runtime security integrates with existing operations, while observability and AI enhance threat modeling and risk assessment. The straightforward deployment of Contrast Security’s solutions is also emphasized.
Transcript
Hey everyone. We're back here. Live at RSA conference.
It's Wednesday morning. Things are starting to kick up here. We've already had a full day.
Of course, we recorded our Textron gang at about eight o'clock this morning. Then we did a new segment special here for RSA called the Analyst Arc with uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference. My next guest needs no introduction to our audience here.
He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right. Early on with Opsis, everything else.
Uh, he is also a co-founder, right? No, you're not. You're C-T-O-C-T-O-N, Founder at Contrast and founder of Contrast Security.
Yep. My friend Jeff Williams. I knew you were co-founder, but I always say CEO and it's Ct.
Right? Right. That's why I wanted to make sure I got it right.
Jeff. CEO's a terrible job. C CTO's a much better job.
CTO's the job you want. I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess.
Yep. You live and learn. Anyway, Jeff, it's great to see you here.
Good to see you too. What Is this? Maybe seven, eight RSAs maybe more.
Yeah. I've, I've done Yeah. More like probably 12.
Well, I'm saying that you and I have interviewed together Yes. Lot. Oh.
I've become an RA since 2002. Right. So Yeah.
You're similar kind of thing. Um, you know what, Jeff, let's start off though. Maybe there are some people out here don't know contrast security.
Just quickly. Yeah. If you don't mind.
Yeah. So We're an application security company. Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things.
Mm-hmm. And we take a runtime approach to application security. So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use.
Like it's all measured directly from a running application. So it's real, it's not theoretical results. Right.
And, uh, we do that to keep you safe and more importantly your customers and children safe. Absolutely. Well, no kidding With children Safe.
You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focused on, the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes. Right?
And that's like sort of a black hole, right? That deployment event horizon. Yeah.
And all of our, and if we could say all of our AppSec focuses left of that horizon. That's Right. Traditionally, Traditionally.
And, and for good reason, it's supposedly faster, cheaper, more efficient. Well, we should talk about that. Absolutely.
But recently, I know Contrast, what was the movie Interstellar? Remember that movie? Yeah.
You've gone through the event Horizon. That's Right. Through the event Horizon.
We're gonna come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right. Uh, and to me that's what sets you apart, I don't know, is the CTO, you have a better handle on this than me, but as an observer, that's what sets it apart.
Well, you're exactly right. Traditionally, we've put a lot of bets down on helping developers write perfect code. Yep.
But I, I don't know, do you feel like developers writing perfect Code? I don't think there is such a thing as perfect code as the problem. Yes.
And, and it's, I think it's like a holy grail and It's a moving target. Yeah. 'cause stuff changes.
Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities And look, so we've put a lot of bets on that. Yeah. And frankly, it's not delivering.
Right. Right. Like most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work.
Mm-hmm. And so we had, uh, the insight to say, Hey, you know what? In production we can see everything.
It's not, you know, in, in development you see pieces of applications. You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs all separately.
But in production, they're all assembled together. You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly.
Where it's vulnerable. And you can help companies focus on the, you know, the few percentage points of issues that are real. The ones that have crossed the event horizon that are actually being attacked in production.
Mm-hmm. Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems.
So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left Right. Problem is, it just hasn't worked. It's, it's backfired.
com. 'cause I think people realize that you, when you over shift left, what are you saying Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code? No.
Developer says that. But you don't have developers raising their hand and say, I'm your security guy. Also.
True. That's not who they are. Also True.
And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it. Yeah.
So the way runtime security works is, is very much like other kinds of detection and response. Mm-hmm. Like EDR and CDR.
Sure. The one thing to realize those technologies don't stop application layer attacks, right? Yeah.
They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer. Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs.
That's how you detect things with full context. And so after that, it, it works just like the rest of the XDR ecosystem. Sure.
You, you know, telemetry gets collected. It, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations.
Agreed. It's just missing. Agreed.
Let me ask you a question. Yeah. I was at Q con in London last month.
Observability. Yeah. Everything's observability.
It is. How does the a DR play in the observability, this new universe of observability? Yeah.
It's a very similar concept. In fact, we call it security observability in a lot of contexts. Fair Enough.
And Observability is interesting. It started to the left of boom, like in, in development. Mm-hmm.
And companies like New Relic and AppDynamics and so on, you'd monitor development. And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load.
And they're like, well this doesn't, it's not realistic. 'cause they didn't have the right context. So those tools moved into production and they measure real reality in production.
Yep. Uh, and that's the same transformation that AppSec is going through. Yeah.
That's, if you measured in test environments, you don't have enough context. You don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Get.
Walking in that same footsteps Here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So, and our never-ending quest for the single plane of glass be you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform.
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure. And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a junk.
'cause it's different users, right. I think today, but ultimately if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin.
And, and that's, it's come a long way now too, especially with ai. It has. So we're building a digital twin of your application layer.
Not one app at a time, but the whole thing. So That, wait, this is new to me from you now. Yeah.
Let's start over here. Yeah. So talk to me.
So Imagine you've, you're a big complex enterprise. You've got hundreds of thousands of applications all connected to each other, APIs containers. Right.
All confusing. So when you deploy contrast, you can deploy it across that infrastructure. Like we got a Kubernetes operator.
You just push it out. It's part of platform engineering, right? Absolutely.
You push it out, then the telemetry starts coming in and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities? Where are the attacks?
Where are the assets? All that's coming together. And we're building a digital twin.
It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works. It's a lot like the wiz graph except for it's not infrastructure.
We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well I understand this vulnerabilities in this app, which has this blast radius.
And you can really get good risk rating. And you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your pen testing process. No, I'm, I'm a big believer in the digital twinning.
I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or Well, that's bigger Pictures. That's what we had to do, is it's not our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right.
And that's limited work, right? So we moved to a modern streaming data architecture. It's Kafka, it's graph databases.
And we're, we've built a massively scalable data collection platform. That's what you can do that. It's, It's because our new from Splunk Oh.
So obviously, Yes. And he came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry building a a, a awesome Model.
Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff. Exactly. When you start seeing insights that you, you, you just couldn't see before.
Runtime security and AI go together, peanut butter and jelly. Like no doubt they're, because runtime is is real. It's measured directly from running apps.
It's not theoretical stuff. It's not tons of false positives. So yeah.
They, they go together really well. Love it. All right.
This camera's on you. Right? Okay.
Tell them how they get, how did they go get this today? Yeah. Uh, it's, it's easy.
I mean, you can go to our website, you can learn a little more. com. Right.
Okay. And, uh, there's stuff you can try. If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you.
But the, the deployment process is easy. You get our installer, you push it out to your, your containers or your workloads, wherever they are. Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications.
Right. We support all of that. And, uh, almost immediately the telemetry will start flowing.
Uh, particularly if you deploy in production. And that's really where I think you should Yeah. Put it.
Then you're gonna see you, you'll get amazing visibility into what's happening. I will tell you, you're probably in for some surprises. Like there's probably a lot more attacks going on in your application than you, you thought.
Yep. And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach. That's scary.
You may find some log for shell that you didn't know about. By the way, we Always, it seems it's all out there still, Jeff. Good stuff.
Really good. I'm really, you know, it's not often I get to hear new stuff like, hey, Application security has, has not been innovating as fast as it do. Yeah.
Don't know It. Uh, you know, with, with the boom coming from AI development, I mean, if you're, if You're producing how you get our ducks and going 50% more code or a hundred percent more code, I, I don't, you gotta find AEC team is gonna double. So you need technologies to help you scale into that double.
We Don't have enough abec team as it is for what we were producing exactly three years ago. Anyway. Hey man, this is great.
I love it. Appreciate you're doing a, a great job, Jeff. Man, you're the best.
Alright. Jeff Williams, contrast security. Go check out what he was talking about here because this is the kind of stuff you are going to need.
Not three years from now, not two years from now. Now we need it now. Go check it out.
We're live at RSA conference. We'll be back in a minute.